{"id":"CVE-2026-90256","published":"2026-09-17T17:17:21.980","lastModified":"2026-09-18T18:17:51.170","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind\n\nhci_conn::l2cap_data is accessed without locks in l2cap_disconn_ind via\nhci_conn_timeout (disc_work) -> hci_proto_disconn_ind ->\nl2cap_disconn_ind.  This is UAF if the l2cap_conn is deleted\nconcurrently.\n\ndisc_work is disabled sync in hci_conn_del(), so we cannot take\nhci_dev_lock in disc_work.\n\nFix by using proto_lock to guard l2cap_data, in addition to hdev->lock\nwhich is held in other access paths.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/2b66c83ff1751d6bd3201b3017206262ab46dc05","tags":[]},{"url":"https://git.kernel.org/stable/c/b495a3a9b33bc4e4613e685bf5c96c136caa22d8","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability allows for a use-after-free condition in the Linux kernel's Bluetooth L2CAP implementation, which could lead to a denial of service or potentially other issues if exploited.","exploitability":"Exploitation requires concurrent deletion of a l2cap_conn while accessing hci_conn::l2cap_data, making it moderately difficult to exploit.","blast_radius":"If exploited, this could result in a denial of service for Bluetooth services on affected systems.","remediation":"Upgrade to the fixed version 5.19-rc1 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["dos","bluetooth","kernel"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:25:26.669Z"}}